CVE-2024-24573

CVSS V2 None CVSS V3 None
Description
facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POST request containing user information is sent to the endpoint server/fm-modules/facileManager/ajax/processPost.php. It was found that non-admins can arbitrarily set their permissions and grant their non-admin accounts with super user privileges.
Overview
  • CVE ID
  • CVE-2024-24573
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-31T22:33:11.697Z
  • Last Modified Date
  • 2024-01-31T22:33:11.697Z
History
Created Old Value New Value Data Type Notes
2024-06-26 04:17:26 Added to TrackCVE